Webmin 1.955

CPE Details

Webmin 1.955
1.955
2021-08-13
16h21 +00:00
2021-08-16
11h06 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:webmin:webmin:1.955:*:*:*:*:*:*:*

Informations

Vendor

webmin

Product

webmin

Version

1.955

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-45692 2024-09-03 22h00 +00:00 Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.
7.5
High
CVE-2023-52046 2024-01-24 23h00 +00:00 Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute cron job as" tab Input field.
4.8
Medium
CVE-2023-43309 2023-09-20 22h00 +00:00 There is a stored cross-site scripting (XSS) vulnerability in Webmin 2.002 and below via the Cluster Cron Job tab Input field, which allows attackers to run malicious scripts by injecting a specially crafted payload.
4.8
Medium
CVE-2022-36446 2022-07-25 03h56 +00:00 software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
9.8
Critical
CVE-2022-30708 2022-05-15 00h30 +00:00 Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virtualmin or Cloudmin). This occurs because settings-editor_write.cgi does not properly restrict the file parameter.
8.8
High
CVE-2022-0829 2022-03-02 11h10 +00:00 Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
8.1
High
CVE-2022-0824 2022-03-01 23h00 +00:00 Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
8.8
High
CVE-2020-35606 2020-12-21 18h19 +00:00 Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
8.8
High